Three waves in, the Coldcard hardware wallet exploit is not slowing down. Galaxy Research has confirmed that a third round of systematic thefts from Coldcard Bitcoin wallets has pushed total observed losses to approximately 1,367 BTC — a figure now valued at roughly $88 million — spanning 4,585 compromised addresses. The attack is not historical. Wallets are still being drained.

For a device that built its entire brand identity around being the gold standard of Bitcoin self-custody, the breach represents something more severe than a typical security incident. Coldcard hardware wallets have long been marketed to and trusted by technically sophisticated Bitcoin holders: the kind of users who specifically chose hardware-based cold storage to avoid the custodial risks they associate with exchanges and software wallets. The irony that these users are now the victims of a sustained, multi-wave attack is not lost on anyone watching this unfold.

What Galaxy Research Is Tracking

Galaxy Research's analysis — tracking the exploit across its now three distinct phases — paints a picture of an attacker or coordinated group operating methodically rather than opportunistically. The progression from a first wave to a third, with losses accumulating to 1,367 BTC across 4,585 addresses, suggests reconnaissance, systematic identification of vulnerable wallets, and deliberate execution. This is not a smash-and-grab. The breadth of affected addresses — more than four and a half thousand — implies either a flaw that exposes a large class of Coldcard-generated wallets or access to seed phrases through a vector that affects many devices at scale.

The $88 million valuation anchors this squarely among the more significant hardware wallet security events in Bitcoin's history. For context, hardware wallet exploits of this magnitude are rare precisely because the attack surface is theoretically much smaller than hot wallets or exchange infrastructure. Compromising cold storage requires either a physical vulnerability, a supply chain attack, a flaw in key generation, or access to seed storage mechanisms. Galaxy Research has not yet publicly attributed the exploit to a specific root cause based on the available snippet, but the wave-based pattern of ongoing draining suggests the underlying vulnerability or access mechanism remains active and unpatched or unclosed.

The Self-Custody Paradox

This episode forces a reckoning with a foundational assumption in Bitcoin culture. The dominant narrative — "not your keys, not your coins" — has driven a significant cohort of Bitcoin holders toward hardware wallets as the definitive answer to custodial risk. Coldcard, in particular, became something of a status symbol among self-sovereignty advocates: open-source firmware, air-gapped operation, no Bluetooth, no wireless attack surface. The device was chosen specifically because it minimized trust assumptions.

Yet here, 4,585 addresses tied to those very devices have been emptied to the tune of $88 million. This does not invalidate the case for self-custody broadly, but it demands a more sophisticated conversation about what hardware wallet security actually guarantees. A hardware wallet protects private keys from remote software attacks. It does not necessarily protect against vulnerabilities in the key generation process itself, supply chain tampering, or exploits that sit upstream of the signing operation. Whatever the root cause ultimately proves to be, the losses here are real and ongoing.

An Evolving and Active Threat

The most alarming element of Galaxy Research's findings is the word "keep" — attackers are continuing to drain wallets. A third wave implies that either affected users have not been adequately warned and prompted to move funds, or the attacker has access to credentials that users cannot easily invalidate without moving their Bitcoin to entirely new seed phrases and addresses. In either scenario, the remediation burden falls on individual holders who may not be monitoring security bulletins or may not understand the urgency.

The scale of 4,585 affected addresses also raises questions about notification. Unlike a centralized exchange breach, where a company can freeze accounts and push alerts to a known user base, hardware wallet exploits hit a decentralized population of individuals with no unified communication channel. Coldcard and Galaxy Research face the practical challenge of reaching thousands of potentially at-risk users before a fourth wave materializes.

What This Means for the Hardware Wallet Industry

The $88 million Coldcard exploit will reverberate beyond a single product. Hardware wallet manufacturers including Trezor, Ledger, and others will face renewed scrutiny from security researchers and institutional clients asking harder questions about key generation auditing, supply chain integrity, and firmware verification. Institutional Bitcoin holders — already cautious about hardware wallet custody at scale — will point to 1,367 BTC in confirmed losses as evidence that even the most paranoid cold storage setups carry residual tail risk.

For individual Bitcoin holders with Coldcard devices, the immediate priority should be treating any existing Coldcard-generated addresses as potentially compromised and migrating funds to freshly generated wallets with verified, clean seed phrases — ideally on a device with confirmed, unaffected firmware. Waiting for a fourth wave is not a strategy. Galaxy Research's data makes clear this threat is active, not historical, and the total losses figure of $88 million may still be climbing.

Written by the editorial team — independent journalism powered by Bitcoin News.